Description
Dolibarr before 24.0.0 contains a broken object-level authorization vulnerability in the REST API company bank account write routes that allows authenticated attackers with third-party creation rights to create, replace, or delete bank account details of any company without requiring read access to that company. Attackers can inject attacker-controlled IBANs as creditor accounts, which are then written into regenerated SEPA credit-transfer files, redirecting outgoing payments to attacker-controlled accounts.
Published: 2026-08-24
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized bank account manipulation leading to payment redirection
Action: Patch Immediately
AI Analysis

Impact

Dolibarr versions prior to 24.0.0 contain a broken object‑level authorization flaw in the REST API bank account write routes. An authenticated attacker who has third‑party creation rights can create, replace, or delete bank account records for any company without needing read access to that company. By injecting attacker‑controlled IBANs as creditor accounts, the attacker can cause regenerated SEPA credit‑transfer files to point to their own accounts, thereby redirecting outgoing payments.

Affected Systems

The affected system is Dolibarr. Versions before 24.0.0 are vulnerable. Any deployment that exposes the REST API for company bank accounts to authenticated users with third‑party creation rights is at risk.

Risk and Exploitability

The CVSS score of 7.1 indicates a medium‑to‑high severity. The exploitation requires legitimate authentication with appropriate third‑party rights; no additional privileges are needed. Based on the description, it is inferred that financial loss and breach of integrity are possible if redirected payments are processed. Because the vulnerability is not currently listed in the CISA KEV catalog and no EPSS score is available, its current exploitation probability is uncertain, but the potential for significant monetary impact is high. Remediation is strongly recommended for organizations running vulnerable versions.

Generated by OpenCVE AI on August 24, 2026 at 21:03 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Dolibarr to version 24.0.0 or newer.
  • Restrict third‑party creation rights and enforce least‑privilege principles for users with API access.
  • Audit SEPA transfer logs for unexpected changes to creditor IBANs and verify that all bank account records are legitimate.

Generated by OpenCVE AI on August 24, 2026 at 21:03 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 24 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Dolibarr
Dolibarr dolibarr
Vendors & Products Dolibarr
Dolibarr dolibarr

Mon, 24 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 24 Aug 2026 19:15:00 +0000

Type Values Removed Values Added
Description Dolibarr before 24.0.0 contains a broken object-level authorization vulnerability in the REST API company bank account write routes that allows authenticated attackers with third-party creation rights to create, replace, or delete bank account details of any company without requiring read access to that company. Attackers can inject attacker-controlled IBANs as creditor accounts, which are then written into regenerated SEPA credit-transfer files, redirecting outgoing payments to attacker-controlled accounts.
Title Dolibarr < 24.0.0 REST API Broken Object-Level Authorization via Bank Account Routes
Weaknesses CWE-639
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Dolibarr Dolibarr
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-08-29T11:47:38.074Z

Reserved: 2026-08-06T20:42:17.834Z

Link: CVE-2026-71507

cve-icon Vulnrichment

Updated: 2026-08-24T20:01:08.366Z

cve-icon NVD

Status : Deferred

Published: 2026-08-24T19:16:50.110

Modified: 2026-09-08T20:23:49.880

Link: CVE-2026-71507

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-24T21:15:07Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key